ci: gate the release genesis key behind the releases environment - #316
Conversation
CI Summary
Deploy ContractsDeployed addresses vs the expected setExpected is the committed expected-address set; actual is this CI deployment of the same pipeline.
Labelsother, type: docs |
|
Overall looks good, just a few nits: A short section in RELEASE_ARTIFACTS.md would be good regarding the environment name, the two entries and which is a secret vs a variable, the required reviewers, the ref patterns, and the note that a Rn the orger is checkout, setup-foundry, setup-bun, setup-node, build contracts, run tests, then this check. Can we add the check right after setup-foundry, this was any incorrect key gives error way before we execute the other intense ops. |
|
One question: The deployment branch policy allows master and v[0-9]*. Both workflows also accept |
Both taken in e0d1244 , the check now runs after the foundry step and the publishing section of |
Confirmed, and it's intended: releases should only cut from master, so a dispatch from another branch stopping at the environment gate is the desired outcome. Added it to the PR's breaking changes. Also added a new tag ruleset to restrict permissions for creating |
Description
The genesis owner key
DOTNS_ADMIN_KEYwas a repository-level secret, readable by any workflow on any branch, with a silent mnemonic fallback deciding the owner when unset.releasesenvironment: reviewer approval required, refs limited tomasterandv[0-9]*tags, key stored as an environment secret.DOTNS_ADMIN_ADDRESS, so a mistyped key fails before a genesis is built.Follow-up once merged: delete the repository-level
DOTNS_ADMIN_KEYandDOTNS_ADMIN_MNEMONIC, whose last consumers this PR removes.Type
Scope
Related Issues
Fixes
Checklist
Code
forge buildpassesforge testpassesTesting
Security
selfdestructordelegatecallDocumentation
Breaking Changes
Breaking changes: a release run now requires the
releasesenvironment to exist withDOTNS_ADMIN_KEYandDOTNS_ADMIN_ADDRESSconfigured, and pauses for a reviewer approval. Building a genesis locally with onlyDOTNS_ADMIN_MNEMONICset no longer works; passDOTNS_ADMIN_KEY.workflow_dispatchreleases can only be started from master; a dispatch from another branch stops at the environment gate.How to test
The full gate is exercised by the next prerelease: the run must pause on the releases environment, pass the address check, and build with the fresh key.
Notes
The environment itself (reviewers, ref patterns, secret, variable) has already been configured.